pykerberos
High-level interface to Kerberos
Decision gist · record as of 2026-08-14
No. The package is abandoned (last release 2022-03-09) and its own documentation recommends using the upstream package instead. High install friction from C compilation requirements, combined with no active maintenance, makes this a poor choice for new projects. Only consider if maintaining legacy code already using this specific fork.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires system Kerberos libraries and valid Kerberos configuration; C extensions must compile during installation.
- High install friction due to compiled C extensions requiring system Kerberos libraries.
- Package is in abandoned maintenance status with no releases since 2022-03-09; the description explicitly recommends using the upstream package instead.
License · maintenance · safety
ASL 2.0 (permissive) — Licensed under ASL 2.0 (permissive), allowing commercial and private use with minimal restrictions.
last release 2022-03-09 (1619 days) · last repo commit 2022-03-09 · 23 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 1,954,595 downloads/mo, #3,411 on PyPI
Alternatives
Verify before relying
pip install pykerberos
import pykerberos
result, context = pykerberos.authGSSClientInit('http@host.example.com')
pykerberos.authGSSClientStep(context, neg_resp_value)- Whether this fork remains compatible with modern Kerberos versions given its abandoned status since 2022-03-09.
- Current Python 3 compatibility level, as classifiers claim support but package is not actively maintained.
- Whether the recommended upstream package is a direct drop-in replacement or requires code changes.
What it is and what it does
PyKerberos is a high-level Python wrapper around Kerberos (GSSAPI) that abstracts the complexity of building full Kerberos bindings. It provides a limited set of functions for client and server authentication based on RFC 4559, with support for channel bindings that allow authentication to be bound to specific data channels (useful for TLS and services requiring Extended Protection).
The package requires system-level Kerberos libraries to compile and function, and depends on a properly configured Kerberos environment with valid tickets or keytab entries. However, the maintainers have placed this fork on life support, explicitly recommending users try the upstream package instead, as Apple has resumed work on the original project.
Use it for
- Implement Kerberos authentication in Python applications that need to authenticate against Active Directory or MIT Kerberos realms.
- Build client applications that negotiate Kerberos tokens with servers using GSSAPI for single sign-on integration.
- Add channel binding support to TLS-authenticated services to meet Extended Protection requirements.
- Develop server-side Kerberos service principals that validate incoming client authentication tokens.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is abandoned (last release 2022-03-09) and its own documentation recommends using the upstream package instead. High install friction from C compilation requirements, combined with no active maintenance, makes this a poor choice for new projects. Only consider if maintaining legacy code already using this specific fork.
Install
pykerberos on PyPI
Before you install
High install friction due to compiled C extensions requiring system Kerberos libraries. Package is in abandoned maintenance status with no releases since 2022-03-09; the description explicitly recommends using the upstream package instead.
Requires system Kerberos libraries and valid Kerberos configuration; C extensions must compile during installation.
License in practice
Licensed under ASL 2.0 (permissive), allowing commercial and private use with minimal restrictions.
Quickstart
pip install pykerberos
import pykerberos
result, context = pykerberos.authGSSClientInit('http@host.example.com')
pykerberos.authGSSClientStep(context, neg_resp_value)
Verify before relying
- Whether this fork remains compatible with modern Kerberos versions given its abandoned status since 2022-03-09.
- Current Python 3 compatibility level, as classifiers claim support but package is not actively maintained.
- Whether the recommended upstream package is a direct drop-in replacement or requires code changes.
Package facts
| License | ASL 2.0 permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Abandoned 1,619 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 1,954,595 / month, #3,411 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 2Programming Language :: Python :: 3Topic :: Software Development :: Libraries :: Python ModulesTopic :: System :: Systems Administration :: Authentication/Directory |
Evidence: pykerberos-1.2.4.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “kerberos authentication python”
- pykerberosProvides a Python wrapper for Kerberos (GSSAPI) authentication,…
- kerberosProvides a high-level Python wrapper for Kerberos (GSSAPI)…
- pyspnegoHandles SPNEGO, NTLM, Kerberos, and CredSSP authentication protocols;…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also kerberos · winkerberos · scramp · requests-kerberos · k5test · python-kadmin-rs · minikerberos · gssapi · requests-gssapi · pyspnego